VDB
CVE-2007-2524
CVE-2007-2524
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Request System (OTRS) 2.0.x allows remote attackers to inject arbitrary web script or HTML via the Subaction parameter in an AgentTicketMailbox Action. NOTE: DEBIAN:DSA-1299 originally used this identifier for an ipsec-tools issue, but the proper identifier for the ipsec-tools issue is CVE-2007-1841.
EPSS 5.80% · 90.7th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
5.80%
90.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| otrs | otrs | 2.0.4 |
Timeline
- May 8, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- ADV-2007-1698 vdb
- http://www.virtuax.be/?page=library&id=35&type=Exploits url
- 20070611 Re: [SECURITY] [DSA 1299-1] New ipsec-tools packages fix denial ofservice mailing-list
- otrs-indexpl-xss(34164) vdb
- 23862 vdb
- 25205 third-party-advisory
- 35822 vdb
- DSA-1298 vendor-advisory
- 2668 third-party-advisory
- SUSE-SR:2007:013 vendor-advisory
- 20070507 OTRS <= 2.0.x XSS/XSRF mailing-list
- 25787 third-party-advisory
- 25419 third-party-advisory
- 35821 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2007-2524 advisory